CVE-2025-36372
Received Received - Intake

IBM Db2 Information Disclosure Vulnerability

Vulnerability report for CVE-2025-36372, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-30

Last updated on: 2026-06-30

Assigner: IBM Corporation

Description

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information to an authenticated user from the monitoring and event tables.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-30
Last Modified
2026-06-30
Generated
2026-07-01
AI Q&A
2026-06-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ibm db2 From 11.5.0 (inc) to 11.5.9 (inc)
ibm db2 From 12.1.0 (inc) to 12.1.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-538 The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in IBM Db2 for Linux, UNIX, and Windows (including Db2 Connect Server) allows an authenticated user to disclose sensitive information from monitoring and event tables.

This issue is caused by sensitive information being inserted into externally accessible files or directories, classified under CWE-538.

It affects Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 across all platforms.

Impact Analysis

This vulnerability can lead to unauthorized disclosure of sensitive information to authenticated users who should not have access to such data.

Since the vulnerability exposes sensitive data from monitoring and event tables, it could compromise confidentiality within your database environment.

The CVSS base score of 5.5 indicates a moderate severity impact, primarily affecting confidentiality but not integrity or availability.

Detection Guidance

IBM has not disclosed detailed exploitation steps or specific detection commands for this vulnerability to prevent potential misuse.

The vulnerability involves sensitive information disclosure via monitoring and event tables to authenticated users, so detection would likely involve monitoring access to these tables and reviewing logs for unusual queries or access patterns.

Mitigation Strategies

To mitigate this vulnerability, customers should promptly download and apply the appropriate interim fixes provided by IBM from IBM Fix Central for the affected Db2 versions.

IBM suggests using the DB2REMOTE alias for mitigation in supported environments, although no explicit workarounds are recommended.

Additionally, customers should monitor IBM’s security bulletins for updates and ensure that unsupported or end-of-life versions are not in use, as they are not affected.

Compliance Impact

This vulnerability in IBM Db2 could lead to the disclosure of sensitive information to authenticated users via monitoring and event tables.

Such unauthorized disclosure of sensitive data may impact compliance with data protection regulations and standards like GDPR and HIPAA, which require strict controls to prevent unauthorized access to sensitive information.

Organizations using affected versions of IBM Db2 should apply the provided fixes promptly to mitigate the risk of sensitive data exposure and maintain compliance with these regulations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-36372. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart